Cribl targets SIEM data costs with new Detect tool

Cribl touts cost savings as its Detect tool joins a wave of SIEMs that split analytics from data repos, but will it be enough to convince enterprises to switch?

Observability vendor Cribl officially entered the SIEM market this week with the launch of its Detect product, positioning its existing data routing capabilities as a natural fit for a new era of modular SecOps tools.

Cribl began as a log management system that reduced the data users sent to Splunk's analytics backend, prompting a high-profile lawsuit from Splunk that was eventually settled. Cribl has since expanded into AI-based telemetry management and data routing tools that feed and optimize data volumes sent to multiple observability and security systems.

Cribl took its first steps into SecOps workflows with the acquisitions of data engineering vendor CardinalOps in July and incident triage and investigation player Radiant Security in August. Now, IP from those deals and the company's existing streaming analytics and federated search capabilities will be combined into a full-fledged Security Information and Event Management (SIEM) product, Cribl Detect.

Federated data access will also likely help Cribl challenge incumbent SIEM vendors, including Splunk, which have more recently moved into federated search and adjusted pricing to accommodate high data volumes, but haven't traditionally taken that approach, said Steve Koelpin, principal AI observability engineer at a Fortune 50 company he requested not be named because of policies prohibiting him from representing it in the press. Koelpin is a longtime user of both Splunk and Cribl tools.

"The part I'd take seriously with Cribl Detect is its federation: running detections and investigations against data where it already sits, without moving historical data first," Koelpin said. "Migration cost is what keeps most shops on the SIEM they complain about, and this goes straight at it."

Cribl claims Detect can conduct federated searches without rehydration delays on cold storage, which Koelpin said "is the claim that matters most, and the one I'd test first with a hunt across months of data."

Detect represents a foray into a new market for Cribl, but it's built on a similar premise to its original product, with a similar pledge to cut customer costs by up to 50% compared to existing SIEM tools.

"Cribl Detect is priced on the infrastructure it runs on, not on how much you search," wrote Nicole Beckwith, senior director of security engineering and operations at Cribl, in an email this week. "At list price, that works out to roughly $18,000–$20,000 per TB per month, and it scales down with volume. Unlike ingest- or query-based models, there's no analysis tax: teams can investigate, hunt, and re-analyze their data as often as they need without paying again each time."

Analysts slot Cribl into broader modular SecOps trend

Cribl is the latest entrant into a market for tools used by security operations center (SOC) analysts, including SIEM and Security Orchestration, Automation and Response (SOAR), that separates data management and storage from the analytics workflows they feed, but it isn't the first, said Michelle Abraham, an analyst at IDC.

A conversational interface does not remove the need for complete data, dependable queries, or investigation results that hold up to scrutiny.
Sean Sosnowski, Research director, Software Analyst Cyber Research

"The first wave was several years ago with federated [tools] from Panther, Hunters, and others," Abraham said. "Now, we are seeing vendors who started with AI SOC [tools], like 7AI, offer federated SIEM … and existing SIEM vendors are increasing their federated storage options."

AI also changes how SOC analysts interact with those systems, and how they're built, said Sean Sosnowski, a research director at Software Analyst Cyber Research in Toronto.

"They may spend less time writing queries and assembling context as agents take on more of that work," Sosnowski said. "But the evidence and detection infrastructure still have to be reliable. A conversational interface does not remove the need for complete data, dependable queries, or investigation results that hold up to scrutiny."

As a newcomer to the space, Cribl also faces a potential uphill battle to convince customers to migrate from established SIEM tools, especially those with large deployments, Koelpin said.

Existing Splunk and Sigma detection content can be migrated through assisted translation and mapping workflows, with validation and tuning required for the target environment, Beckwith wrote.

"'Assisted translation' for Splunk and Sigma rules is honest, but it means migration is still a real project, not a switch," Koelpin said. "My guess is most large enterprises won't rip out their SIEM on day one. The realistic wedge is the data they already route around their SIEM because it was too expensive to index. Detect finally lets them run detections on it."

Cribl Detect isn't yet supported on-premises or in self-managed environments, a showstopper for potential customers in regulated industries, Koelpin said, though these options are under consideration, according to Beckwith.

Cribl StreamAI gateway uses new custom benchmark

Cribl also unveiled an AI gateway this week based on a similar data-routing and cost-cutting premise, using its own SecIT Bench tests to evaluate the accuracy and cost of AI models before routing workloads to reduce costs.

"Inference is free when StreamAI chooses the model," wrote Nikhil Mungel, Head of AI R&D at Cribl, in an email this week. "Requests that are sent directly to a specific model are billed at the provider’s published token rates, with no Cribl markup. Cost is logged for every call, so customers can verify their savings."

Initial SecIT Bench tests evaluated 20 AI models across 30 real-world IT and security investigations, and Cribl claims the results showed a 17% spread in diagnostic accuracy, compared with a 20x range in cost across models.

As with modular SIEM tools, Cribl is far from alone in rolling out an AI gateway in 2026 – vendors from a multitude of markets, including SaaS providers, DevSecOps, observability and SecOps have launched similar offerings this year.

For Koelpin, Cribl's AI gateway price is right.

"Free inference when the router picks the model, and provider rates with no markup when you pick, removes the worry that the gateway eats the savings," he said.

However, Koelpin said that StreamAI's latency, which depends on each customer's environment, "is the first thing an ops team will ask" before deploying it.

Saving tokens by finding the model with the best cost/accuracy ratio is a promising approach, said Torsten Volk, an analyst at Omdia, a division of Informa TechTarget.

"If Cribl is right, and the accuracy spread is only 17% while the cost spread is 20x, there is a lot of savings potential, compared to a standard AI gateway that only decides based on static rules, such as which team sent the request, which provider is allowed, or whether the monthly budget is used up," Volk said.

However, Volk added, "How big of an impact this could make is now up to the accuracy of Cribl's SecIT Bench results."

Beth Pariseau, Lead Editor, IT Infrastructure News for Informa TechTarget, is an award-winning veteran of IT journalism. Have a tip? Email her or connect on LinkedIn.

Dig Deeper on IT Operations